This is at least the third time that RomCom has been caught exploiting a significant zero-day vulnerability in the wild. After immediate notification, WinRAR released a patched version on July 30 th , 2025., 2025. Upon further analysis, we found that the attackers were exploiting a previously unknown vulnerability affecting WinRAR, including the then-current version, 7.12. FilesSHA-1 Filename Detection Description 371A5B8BA86FBCAB80D4 E0087D2AA0D8FFDDC70B Adverse_Effect_Medi cal_Records_2025.rar LNK/Agent.AJN Win64/Agent.GPM Archive exploiting CVE‑2025‑8088; found on VirusTotal. 676086860055F6591FED 303B4799C725F8466CF4 Datos adjuntos sin título 00170.dat LNK/Agent.AJN Win64/Agent.GPM Archive exploiting CVE‑2025‑8088.